Container and Kubernetes Security Questions

Securing containerized and orchestrated workloads. Covers container image scanning and hardening, Kubernetes security (RBAC, network policies, pod security, secrets), runtime protection, and cloud-native security patterns. The specific attack surface and controls introduced by containers and orchestration platforms.

HardTechnical
81 practiced

For a Kubernetes cluster security assessment, outline steps to evaluate the control plane, node and pod security, RBAC configuration, admission controllers, network policies, container image provenance, and runtime behavior. Describe how a misconfigured PodSecurityPolicy or permissive ServiceAccount can be exploited to gain access to the node or cluster.

MediumSystem Design
99 practiced

For a Kubernetes cluster hosting multi-tenant workloads, propose controls across the host (node), container runtime, orchestration (kubelet, API server), and network (CNI) layers to harden the architecture. For each control, describe how a penetration tester would evaluate or attempt to bypass it.

That is every published Container and Kubernetes Security question for Penetration Tester so far. Browse the other topics in this category, or practice this one interactively.